Copilot worm can spread through Microsoft Word docs
Summary
A researcher discovered an 'AI worm' that can spread through Microsoft Word documents by hiding malicious instructions in files that Copilot (an AI assistant) uses as input. When Copilot processes these documents, the hidden instructions execute and copy themselves into newly generated documents, creating a self-propagating attack that bypasses traditional email security because the document only becomes malicious after the AI processes it.
Solution / Mitigation
Microsoft stated they have 'addressed the findings' and use 'a defense-in-depth strategy with safeguards that block malicious instructions at multiple points.' The company also recommended that customers 'install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.' According to the researcher, Microsoft implemented 'multiple small focused mitigations' since March, though the core vulnerability has not been fully fixed.
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4203630/copilot-worm-can-spread-through-microsoft-word-docs.html
First tracked: July 31, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%